Sceawere
Vulnerability Detail
CVE-2026-61936UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Windows Defender Firewall Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Windows 10 Version 1809
- Attack Type
- CWE-862: Missing Authorization
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-08-11T17:18:17.343Z",
"pubdate": "2026-08-11T17:18:17.343Z",
"executiveSummary": "A security feature bypass vulnerability exists within the Windows Defender Firewall Service due to a missing authorization check.\nThis vulnerability allows an authorized local attacker to successfully bypass configured security features on affected systems.\nThe affected product is the Windows Defender Firewall Service.\nThe primary risk implication is the degradation of host-based security controls, potentially enabling malicious actors to evade network filtering rules and security monitoring enforced by the firewall.\nExploitation capabilities require the attacker to possess authorization and execute commands locally on the target operating system.\nThe attack vector is strictly local, requiring no specialized network exposure for successful exploitation.",
"technicalDetails": "The root cause of this vulnerability stems from an insufficient or entirely missing authorization validation check within the internal logic of the Windows Defender Firewall Service.\nThe vulnerable component is responsible for managing firewall states and enforcing security policies across the operating system.\nAn authenticated, authorized local attacker can leverage this missing authorization enforcement to interact with the service improperly.\nStep-by-step exploitation occurs as follows: first, the attacker establishes a local session on the target system with the necessary base authorization level. Second, the attacker interacts directly with the vulnerable Windows Defender Firewall Service application programming interfaces or control mechanisms. Third, because the service fails to adequately validate the authorization context for the requested operation, the attacker bypasses the intended security feature restrictions. Finally, the attacker achieves an unauthorized state alteration or policy evasion, neutralizing the defensive enforcement capabilities of the firewall.\nPrivilege requirements dictate that the attacker must be authorized on the local machine, though the missing authorization flaw permits actions beyond the intended scope of those privileges.\nThe network exposure is entirely local, meaning remote attackers cannot exploit this vector directly without prior local access or remote code execution primitives.\nPost-exploitation impact includes the circumvention of security boundaries enforced by the firewall, potentially facilitating lateral movement, data exfiltration, or the deployment of secondary payloads that would otherwise be blocked by network inspection and filtering rules."
}